Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing Authorization Check in SCM-APO-SCC, SAP security note 1522666

SAP Note 1522666
SAP Security Note
Medium priority

SAP security note 1522666, "Missing Authorization Check in SCM-APO-SCC", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSupply Chain Management > Advanced Planning and Optimization > Supply Chain Cockpit (SCC): USE SCM-BAS-MD
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on14.12.2010
LanguageEnglish

Description

Symptom

An authenticated user can use functionality of SCM-APO-SCC and SCM-BAS-MD-TL to which access should be restricted. This can potentially result in an escalation of privileges.

Solution

Implement the attached correction instruction.

Reason and prerequisites

SCM-APO-SCC and SCM-BAS-MD-TL lack permission checks for an authenticated user’s authorization to access some of its functionality. This may result in undesired system behavior.

Affected components

  • SAP_APO 30A
  • SAP_APO 310
  • SCM 400
  • SCM 410
  • SCM 500
  • SCM 510
  • SCM_BASIS 510

Full note on SAP: SAP Support Launchpad note 1522666

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More